Include the email of malicious sender and malicious link in Huntress lockout incidents
S
Sabina Hasanova
Hi All!
Currently when we get incidents generated on Huntress in case if this is a phishing attack and the user clicked on the link, we only get the IP attack occurred from. It would be extremely useful if we had the email of malicious sender and the contents of the email so we could have an idea how this has happened. Currently there no such function in place, I got a confirmation with Huntress support. On the top of that, it would be awesome to see what other mailboxes have received it an also if they interacted with the email and its content and purging the malicious email out of the mailboxes. Another useful function would be blocking the malicious sender for a set period of time. A product called "Phishier" of Knowbe4 has that functionality for reference